When auditing the transparency of an AI system, which of the following would be the MOST effective way to understand the model's decision-making process?
An organization is using information gathered from customer accounts to train its AI chatbot. Which of the following is the GREATEST risk associated with this practice?
An IS auditor uses an internally developed generative AI tool to prepare a status update for audit stakeholders. Which of the following is the auditor’s MOST appropriate course of action?
Which of the following is the GREATEST risk associated with using AI in audit planning?
Which of the following is MOST important to have in place when initially populating data into a data frame for an AI model?
The BEST way to prevent sensitive information disclosure by large language model (LLM) chatbots is through:
An organization uses an AI image generation platform to create promotional materials. An IS auditor identifies that the platform includes copyrighted images in its training data. Which of the following is the auditor's BEST recommendation to address this issue?
A generative AI system has a validation control in place to reject inappropriate questions by checking them against built-in ethical standards. Which of the following enables malicious actors to circumvent this control through prompt engineering?
An organization is evaluating change management practices for AI-based decision support models. Which of the following BEST demonstrates effective AI-focused change management?
When auditing a machine learning (ML) solution, false positives can BEST be assessed by examining the level of:
Which of the following will provide the BEST evidence to support the alignment of an AI model with an organization's business objectives?
Which of the following key performance indicators (KPIs) are MOST important when evaluating whether an AI model meets business objectives?
Which of the following is MOST important to consider when deciding whether to implement an AI solution?
When using off-the-shelf AI models, which of the following is the MOST appropriate way for organizations to approach vendor management?
An organization is adopting AI for its procurement and inventory teams, raising concern from stakeholders that they will lose their jobs due to AI. Which of the following is the BEST way for the IS auditor to assess whether the potential negative impacts were minimized?
During a pre-implementation risk assessment, an AI model is determined to present a significant risk of bias and potential harm in excess of the organization’s risk tolerance. Which of the following is the MOST appropriate response?
An IS auditor notes that an AI model achieved significantly better results on training data than on test data. Which of the following problems with the model has the IS auditor identified?
Which of the following is the MOST important consideration when auditing the data used for training an AI model?
Which of the following AI system characteristics would BEST help an IS auditor evaluate the system's algorithm?
Which of the following is an IS auditor's MOST important course of action when determining whether source data should be entered into approved generative AI tools to assist with an audit?
Which of the following is the MOST important course of action for an organization prior to allowing end users to utilize an AI tool?
Which of the following is the PRIMARY purpose of an AI acceptable use policy?
An organization shares an AI model with external partners. One partner reports that sensitive data has been inadvertently exposed through the model’s outputs. Which of the following is the IS auditor's BEST recommendation?
The GREATEST benefit of using AI auditing techniques over traditional methods is that AI auditing techniques can:
From a data appropriateness and bias perspective, which of the following should be of GREATEST concern when reviewing an AI model used in a credit scoring system?
The PRIMARY objective of auditing AI systems is to:
The PRIMARY objective of machine learning (ML) in data processing is to: